CVE-2019-6159

MEDIUMCVSS 6.1/10EPSS 1.09%

Last modified

CVE-2019-6159 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A stored cross-site scripting (XSS) vulnerability exists in various firmware versions of the legacy IBM System x IMM (IMM v1) embedded Baseboard Management Controller (BMC). This vulnerability could allow an unauthenticated user to cause JavaScript code to be stored in the IMM log which may then be executed in the user's web browser when IMM log records containing the JavaScript code are viewed. EPSS estimates a 1.09% chance of exploitation in the next 30 days.

Description

A stored cross-site scripting (XSS) vulnerability exists in various firmware versions of the legacy IBM System x IMM (IMM v1) embedded Baseboard Management Controller (BMC). This vulnerability could allow an unauthenticated user to cause JavaScript code to be stored in the IMM log which may then be executed in the user's web browser when IMM log records containing the JavaScript code are viewed. The JavaScript code is not executed on IMM itself. The later IMM2 (IMM v2) is not affected.

Metrics

CVSS 3.1
6.1/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS Probability
1.09%

61.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LenovoBladecenter Hs22 FirmwareAll versions
LenovoBladecenter Hs22v FirmwareAll versions
LenovoBladecenter Hx5 FirmwareAll versions
LenovoSystem X Idataplex Dx360 M2 FirmwareAll versions
LenovoSystem X Idataplex Dx360 M3 FirmwareAll versions
LenovoSystem X3400 M3 FirmwareAll versions
LenovoSystem X3500 M2 FirmwareAll versions
LenovoSystem X3500 M3 FirmwareAll versions
LenovoSystem X3550 M3 FirmwareAll versions
LenovoSystem X3560 M2 FirmwareAll versions
LenovoSystem X3630 M3 FirmwareAll versions
LenovoSystem X3650 M3 FirmwareAll versions
LenovoSystem X3690 X5 FirmwareAll versions
LenovoSystem X3850 X5 FirmwareAll versions
LenovoSystem X3950 X5 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-6159?
A stored cross-site scripting (XSS) vulnerability exists in various firmware versions of the legacy IBM System x IMM (IMM v1) embedded Baseboard Management Controller (BMC). This vulnerability could allow an unauthenticated user to cause JavaScript code to be stored in the IMM log which may then be executed in the user's web browser when IMM log records containing the JavaScript code are viewed. The JavaScript code is not executed on IMM itself. The later IMM2 (IMM v2) is not affected.
How severe is CVE-2019-6159?
CVE-2019-6159 has a CVSS score of 6.1/10 (MEDIUM severity). The EPSS model estimates a 1.09% probability of exploitation in the next 30 days.
How do I fix CVE-2019-6159?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-6159?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST